I ask this in workshops. Who here has used an AI tool for work in the last month? A few hands go up. Then I ask it differently. Who has asked one to tidy up an email, summarise a long document, explain a clause in a contract, or write a formula for a spreadsheet? Most of the room, including several people who kept their hands down the first time.
They were not being dishonest. They did not think of it as using AI. They thought of it as getting something finished faster, which is what it was.
Why a ban produces the opposite of what you want
The work still has to be done by five o'clock and the tool still makes it quicker. Blocking it on the company network moves the same document to a personal phone. Now there is no record of it, no way to know which product it went into, and nobody in your organisation who could answer a question about it a year later.
You have not reduced what leaves the building. You have removed your ability to see it, and you have made an otherwise honest person do something quietly. That is worse in every direction that matters.
The question the policy document cannot answer
When somebody asks where does that data go, they deserve a real answer, and most policies do not contain one. The honest version has a few parts. Which product exactly, because the free version and the paid business version of the same thing often carry different terms. Whether the provider keeps what you send, and for how long. Whether anything you type is used to improve their models. Whether a human being at that company can read it, and under what circumstances.
Those answers exist. They are sitting in the terms nobody in your organisation has read. Somebody should read them once, for two or three products, and write down what each one says in a paragraph. Those paragraphs are worth more than the policy, because they are what makes the policy make sense to the person standing over the paste button.
What a workable position looks like
- Two or three named products that are approved, where somebody has read the terms and the account belongs to your organisation rather than to an individual.
- A short list of what must never go in, written in your own vocabulary: passport and ID copies, payroll, signed contracts, customer lists, anything about a named individual, figures that have not been published yet.
- One plain sentence of reasoning next to each item, so people can apply it to the case you did not think of.
- A named person to ask when something falls between the lines, and an understanding that asking is normal rather than a confession.
- Somewhere to record what people are using it for, so that how are our staff using this has a list for an answer instead of a guess.
One page. If it runs to twelve, it exists to protect whoever wrote it, and nobody in operations will read past the first heading.
The reasoning matters more than the rule. A policy saying no client data in AI tools sounds clear and is not. The person about to paste a supplier price list does not think that is client data. The person summarising a CV thinks of it as a document that was emailed to them, not as information about a real person. Send the rule without the reason and people apply it to the cases they imagined, not to the ones you did.
The commitments you have already signed
Plenty of organisations in the UAE have written commitments about where their records sit and who may see them. Those commitments were signed before there was a free chatbot on every phone in the building, and none of them were drafted with one in mind. If you hold government contracts, handle personal information, or work in a sector with an inspector, the distance between what you promised and what is happening at desk level is worth measuring yourself, before somebody else measures it for you.
Ask for the actual clause rather than for somebody's recollection of the clause. Those two things differ more often than they should, in both directions.
Where to start this month
Ask, with nothing attached to the answer. Not a survey with your name at the top. A manager asking their own team what they have found useful, in a conversation where nobody is in trouble. You will get back a list of products you have never heard of, and at least one way of working that is quietly better than the official one.
Then approve the two that make sense, say what may not go into them and why, and put one person's name next to the awkward questions. That is about a week of effort and it holds up. The alternative is a document describing a building nobody is standing in.
If you want a second opinion on which products you can approve given what your organisation has already signed up to, that is a conversation rather than a project. I am happy to have it.
Working through this on a live programme?
A 45-minute call with the engineer who would run the work. We will tell you whether AI is the answer, including when it is not.